Introduction
Who we are and what this policy covers
EPOSDeck is a cloud-based retail and business management platform offering point-of-sale, inventory, customer, supplier, employee, repair, reporting, barcode, multi-store and related operational features. References to “EPOSDeck”, “we”, “us” or “our” in this policy mean the EPOSDeck business responsible for the relevant website, product or service.
This policy applies to personal data processed through www.eposdeck.com, our applications, platform, demonstrations, customer support, integrations, communications and related services. It does not replace any separate data processing agreement, subscription agreement or customer contract that applies to your organisation.
Important: When a business customer enters information about its own customers, employees, suppliers or other individuals into EPOSDeck, that business generally acts as the data controller and EPOSDeck acts as its processor.
Our role
Controller and processor responsibilities
Our role depends on the context in which personal data is processed:
When EPOSDeck is a controller
We act as controller for information collected directly from website visitors, prospective customers, account administrators, billing contacts and people who contact our team.
When EPOSDeck is a processor
We act as processor when we host or process data entered into the platform by a customer on behalf of that customer and according to its documented instructions.
Data categories
Information we collect
We collect information that you provide, information generated while you use our services and information received from authorised third parties.
Identity and contact data
Name, job title, organisation, email address, telephone number, postal or business address, country and account contact details.
Account and profile data
Username, encrypted password, role, permissions, store assignments, authentication records, preferences and account status.
Business and platform data
Products, stock, transactions, customers, suppliers, employees, repairs, warranties, purchase records, reports, notes, store details and operational information.
Billing and subscription data
Plan, invoice details, billing address, VAT or tax information, transaction references and payment status. Complete card details are handled by payment providers.
Communications and support
Enquiries, demo requests, support tickets, emails, call notes, feedback, survey responses, troubleshooting details and correspondence history.
Technical and usage data
IP address, device and browser details, operating system, pages viewed, feature usage, login events, timestamps, session data, API requests, diagnostics and error logs.
Sensitive and special-category data
EPOSDeck is not designed to require special-category personal data such as health, biometric, religious, political or trade-union information. Customers should not enter such information unless it is necessary, lawful and specifically supported by the service and their own policies. Where a feature processes legally sensitive information, the customer is responsible for establishing an appropriate legal basis and applying suitable controls.
Data from third parties
We may receive information from authorised resellers, implementation partners, payment providers, identity or authentication services, integrations selected by you, analytics providers, publicly available business sources and other parties where permitted by law.
Purposes
How we use personal data
- Provide, operate, maintain and improve the EPOSDeck platform and website.
- Create, authenticate and administer user accounts and role-based access.
- Process subscriptions, invoices, payments, renewals and account changes.
- Deliver demonstrations, onboarding, implementation, training and support.
- Enable platform features, integrations, synchronisation, backups and reporting.
- Respond to enquiries, requests, complaints, feedback and technical incidents.
- Send service notices, security messages, policy updates and administrative communications.
- Understand product usage, diagnose errors, monitor performance and develop new features.
- Protect accounts, prevent fraud, investigate misuse and enforce our agreements.
- Meet legal, tax, accounting, audit, regulatory and contractual requirements.
- Send marketing communications where permitted and allow recipients to opt out.
- Produce aggregated or anonymised insights that do not identify individuals.
UK GDPR and EU GDPR
Legal bases for processing
Automation and AI
Automated processing and intelligent features
EPOSDeck may use automated methods, analytics or artificial intelligence to support activities such as product categorisation, stock insights, anomaly detection, OCR, forecasting, reporting or workflow suggestions. These features are designed to assist users and may not always be accurate.
Unless clearly stated otherwise, EPOSDeck does not make decisions producing legal or similarly significant effects about individuals solely through automated processing. Users should review automated outputs before relying on them for important business decisions.
Transactions
Payments and card information
Subscription and other payments may be processed by approved third-party payment providers. EPOSDeck does not intentionally store complete payment-card numbers, card verification codes or equivalent full card credentials on its own application servers. Payment providers process information according to their own privacy notices and security standards.
Communications
Marketing preferences
We may send product news, educational content, event invitations, offers or related business communications where permitted. You can unsubscribe through the link in an email or contact us directly. We may still send non-marketing communications necessary to provide the service, such as billing, account, support, legal and security notices.
Storage duration
Data retention, export and deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including providing services, maintaining business and financial records, resolving disputes, enforcing agreements, preventing fraud and complying with law.
Retention periods vary according to:
- The type, volume and sensitivity of the information.
- The reason it was collected and whether that purpose continues.
- Contractual, legal, tax, accounting and regulatory requirements.
- Security, fraud-prevention, backup and disaster-recovery needs.
- Customer instructions under an applicable agreement.
When data is no longer required, we delete, anonymise or securely isolate it, subject to backup cycles and legal obligations. Customers should export required business records before account closure or service termination. Residual backup copies may remain temporarily until overwritten according to normal backup schedules.
Protection measures
How we protect information
We use organisational and technical safeguards appropriate to the nature of the service and the risks involved. Measures may include:
HTTPS and transport encryption
Role-based access controls
Authentication and password protections
Logging, monitoring and alerting
Network and infrastructure controls
Backups and recovery procedures
Restricted staff and provider access
Incident response procedures
No online service can guarantee absolute security. Users must protect credentials, apply appropriate permissions, use strong passwords, maintain secure devices and promptly report suspected unauthorised access.
Incident response
Personal data breaches
We maintain processes to assess and respond to suspected personal data breaches. Where required by applicable law, we will notify the relevant supervisory authority and affected individuals or customers within the legally required period. Customers acting as controllers remain responsible for their own notification obligations, and we will provide reasonable assistance where required by our agreement.
Global processing
International data transfers
EPOSDeck and its service providers may process information in countries outside the United Kingdom, European Economic Area or your country of residence. Where required, we use recognised safeguards such as adequacy decisions, approved contractual clauses, the UK International Data Transfer Agreement or Addendum, supplementary security measures or another lawful transfer mechanism.
External services
Third-party links, hardware and integrations
Our website or platform may link to or integrate with payment gateways, accounting tools, email or SMS providers, cloud services, barcode or printing hardware, delivery services and other third-party products. Their processing is governed by their own terms and privacy notices. We are not responsible for independent third-party privacy practices, and you should review them before enabling an integration or providing information.
Age limitations
Children’s privacy
EPOSDeck is a business service and is not directed to children. We do not knowingly collect personal data directly from children under 16 through our website or account-registration process. If you believe a child has provided personal information to us without appropriate authorisation, contact us so we can investigate and take suitable action.
Your choices
Your privacy rights
Depending on your location and applicable law, you may have the right to:
To protect your information, we may need to verify your identity and authority before completing a request. Some rights are subject to legal exceptions. Where EPOSDeck processes data solely for a business customer, we may direct your request to that customer or assist them in responding.
Regulatory concerns
Complaints to a supervisory authority
We encourage you to contact us first so we can try to resolve your concern. You may also complain to the data-protection authority responsible for your location. In the United Kingdom, this is generally the Information Commissioner’s Office. Your right to complain is not affected by contacting us first.
Updates
Changes to this Privacy Policy
We may update this policy to reflect changes to our services, legal requirements or privacy practices. We will publish the revised version on this page and update the “Last updated” date. Where changes are material, we may also provide notice through the website, platform or email. We recommend reviewing this page periodically.
Get in touch
Contact us about privacy
For questions, requests or concerns about this policy or the way EPOSDeck processes personal data, contact us using the details below. Please include “Privacy Request” in the subject line and provide enough information for us to understand and verify your request.
This policy is intended to describe EPOSDeck’s general privacy practices and should be reviewed against the company’s actual processing activities, service providers, registered business details and contractual arrangements before publication.